4 groups caught using the same Chrome and Windows exploit kit
| Source: Ars Technica AI
Tags: BlueMoon, Proofpoint, Chromium, Windows, TA412, China APT, AI-accelerated threats, exploit kit
Four hacking groups — two China state-sponsored — were caught sharing a single 'BlueMoon' exploit kit chaining Chromium and Windows kernel vulnerabilities. Proofpoint cites AI-accelerated vulnerability discovery and Chromium's open-source patch gap as the key enablers that compressed the window from patch to weaponized exploit into days.
Details
Security firm Proofpoint disclosed Wednesday that at least four distinct threat actors are deploying an almost identical exploit chain — dubbed BlueMoon — that strings together two Chromium vulnerabilities and one Windows kernel flaw affecting Windows 10, Windows Server 2019/2022, and the initial Windows 11 release. All three CVEs received patches within the past 24 hours, making rapid patching urgent for enterprise environments. Two of the four groups carry Chinese government ties. TA412, formally indicted by the US in 2024 on behalf of China's civilian foreign intelligence agency, began using BlueMoon on August 28 targeting US NGOs, mining companies, and commodity trading firms. A second China-aligned group, UNK_LateNight, hit US aerospace companies. UNK_DoubleCheck targeted a Vietnamese manufacturer; UNK_QuietRacket focused on Singapore and Indonesia. Proofpoint flagged two structural factors enabling this unusual proliferation. First, a 'patch gap' in the Chromium supply chain: upstream patches are publicly visible before downstream browsers like Chrome and Edge ship them, creating a reversible window for motivated actors. Second — and directly relevant to AI practitioners — AI agents are materially accelerating exploit development. What was historically a rare, high-cost capability appears to have been developed and distributed across multiple threat actors within days. The practical takeaway for security teams: the combination of open-source patch transparency and AI-assisted reverse engineering is collapsing the timeline between public disclosure and weaponized exploit. Organizations should prioritize browser and OS patch cadence and treat the patch-gap window as an active attack surface.